Enhancing Information Security Awareness on Phishing Among It Students: A Pilot Test Case Study at Politeknik Tuanku Syed Sirajuddin

Authors

  • Nor Naematul Saadah Ismail Human Resource Department, Ministry of Higher Education, Malaysia
  • Fatin Izzati Fammy Rikzan School of Computing, Universiti Utara Malaysia, Malaysia
  • Norliza Katuk School of Computing, Universiti Utara Malaysia, Malaysia
  • Nor Laily Hashim School of Computing, Universiti Utara Malaysia, Malaysia
  • Nurul Akhmal Mohd Zulkefli College of Arts and Applied Science, Dhofar University, Oman

DOI:

https://doi.org/10.32890/jdsd2023.1.2

Keywords:

Student awareness, Cybersecurity, Training awareness, Phishing Awareness

Abstract

Students engage with the core operations of university business processes, making them potential targets susceptible to significant cyberattack risks due to their limited experience and knowledge in information security. Consequently, IT students must gain awareness and competence in information security to mitigate potential threats and attacks, including those related to Information Technology (IT) security threats and the loss of valuable information and intellectual assets. This paper aims to assess the Phishing Awareness Program implemented at the Department of Information Technology and Communication (ITC) in Politeknik Tuanku Syed Sirajuddin (PTSS) and its students' awareness level. The significance of this study is focusing on students’ weaknesses and educating them about being cyber victims. Thirty students were involved in participating in this survey. They were given a set of questionnaires and performed pre-test and post-tests. After that, they were given three videos related to phishing and, later, three videos related to the consequences of phishing. Their awareness evaluation was performed after video training had been completed. Even though the score results of the post-test were increased and got positive feedback from respondents, several respondents still got the medium-level score. Suggestion for improvement was obtained to improve the current video content and its implementation. This work contributes to the information security awareness domain, where managers at higher learning institutions can replicate similar processes as proposed in this work in conducting similar training awareness with their students.

References

Burda, P., Chotza, T., Allodi, L., & Zannone, N. (2020). We are testing the effectiveness of tailored phishing techniques in industry and academia. Proceedings of the 15th International Conference on Availability, Reliability and Security. https://doi.org/10.1145/3407023.3409178

CJ, G., Pandit, S., Vaddepalli, S., Tupsamudre, H., Banahatti, V., & Lodha, S. (2018). PHISHY - A Serious Game to Train Enterprise Users on Phishing Awareness. Proceedings of the 2018 Annual Symposium on Computer-Human Interaction in Play. https://doi.org/10.1145/3270316.3273042

Desolda, G., Ferro, L. S., Marrella, A., Catarci, T., & Costabile, M. F. (2022). Human Factors in Phishing Attacks: A Systematic Literature Review. ACM Computing Surveys, 54(8), 1–35. https://doi.org/10.1145/3469886

Gandhi, A. (2017). Quantitative Assessment of Information Security Awareness on Informatics Students in a University. Proceedings of the 2017 International Conference on Information Technology - ICIT 2017. https://doi.org/10.1145/3176653.3176728

Higashino, M. (2019). A Design of an Anti-Phishing Training System Collaborated with Multiple Organizations. Proceedings of the 21st International Conference on Information Integration and Web-Based Applications & Services, iiWAS2019. https://doi.org/10.1145/3366030.3366086

Moul, K. A. (2019). Avoid Phishing Traps. 2019 ACM SIGUCCS Annual Conference on - SIGUCCS ’19. https://doi.org/10.1145/3347709.3347774

Qasaimeh, M., Al-Manaseer, H., Al-Manaseer, H., & Alghanim, F. (2021). Status Update on Phishing Emails Awareness: Jordanian Case. The 7th International Conference on Engineering & MIS 2021. https://doi.org/10.1145/3492547.3492565

Sharevski, F., Devine, A., Pieroni, E., & Jachim, P. (2022). Phishing with Malicious QR Codes. 2022 European Symposium on Usable Security, EuroUSEC ’22. https://doi.org/10.1145/3549015.3554172

Sykosch, A., Doll, C., Wübbeling, M., & Meier, M. (2020). You are generalising the phishing principle. Proceedings of the 15th International Conference on Availability, Reliability and Security. https://doi.org/10.1145/3407023.3409205

Downloads

Published

31-10-2023

Issue

Section

Articles

How to Cite

Ismail, N. N. S., Fammy Rikzan, F. I., Katuk, N., Hashim, N. L., & Mohd Zulkefli , N. A. (2023). Enhancing Information Security Awareness on Phishing Among It Students: A Pilot Test Case Study at Politeknik Tuanku Syed Sirajuddin. Journal of Digital System Development, 1, 12-23. https://doi.org/10.32890/jdsd2023.1.2

Most read articles by the same author(s)